CVE-2026-0239

Chronosphere Chronocollector Information Disclosure Vulnerability

Severity
Medium 4.9
CVSS 4.0
Exploited
Not listed
EPSS
0.002
7.0th percentile
Discovered by
Vendor
Published by the vendor
Published
May 13, 2026
Assigned by palo_alto

Description

An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with network access to the collector service to retrieve sensitive information.

Weakness: CWE-497

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported affected versions (1)
  • Palo Alto Networks · Chronosphere Chronocollector

Credit

Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue.

Vendor remediation

Version Suggested Solution Chronosphere Chronocollector Upgrade to v0.116.0 or later.